Three Security Stories You May Have Missed: Airport Attack, Fake Breach Data, and a Bank Under Pressure

A busy week in cybersecurity produced a cluster of stories that deserve attention: a UK airport group hit by hackers, questions over whether a clothing brand's stolen data was real, and a major US bank pushing back on ransomware claims.

ThreatVectr Newsdesk· 3 min read
Extreme close-up of a glowing server rack illuminated in cold blue light, with reflected light patterns rippling across a dark polished floor, 16:9 framing, pho
Share

Key points

  • Manchester Airports Group confirmed a cyberattack that disrupted operations at multiple UK airports.
  • Data purportedly stolen from workwear brand Carhartt was found to be partly fabricated.
  • US Bank denied the substance of claims made by a ransomware gang, which is a criminal group that locks victims' files and demands payment to restore them.
  • A scare involving Log4j, a widely used piece of software for recording computer activity, raised fresh concerns about a years-old but still dangerous security flaw.

What happened at Manchester Airports?

Hackers hit Manchester Airports Group, which operates Manchester, East Midlands, and Stansted airports in the UK, causing disruption to internal systems. Passengers travelling through those airports may have experienced delays or service outages as staff worked around affected systems.

The attack is a reminder that transport infrastructure sits at the intersection of two uncomfortable realities: it relies heavily on connected computer systems, and it cannot simply go offline while repairs happen. Travellers whose contact details or booking information are held by the airports should watch for unexpected emails or texts, since criminals who steal personal data often use it to send convincing-looking scam messages, a technique called phishing.

Was the Carhartt breach real?

Partly, but not entirely. Researchers examining data that criminals claimed to have stolen from Carhartt, the American workwear company, found that portions of it were fabricated or recycled from older leaks.

This is more common than most people realise. Ransomware gangs and data-theft groups sometimes inflate the value of their hauls by mixing real records with fake ones, or by repackaging data stolen from entirely different companies. It muddies the water for investigators and creates unnecessary alarm for customers. If you have a Carhartt account, changing your password costs nothing and removes one worry.

Why is US Bank in the news?

A ransomware gang claimed to have breached US Bank and threatened to publish stolen data. US Bank responded by disputing the gang's account, as first noted in SecurityWeek's roundup of the week's smaller stories.

Banks are frequent targets for this kind of public pressure, regardless of whether a real breach occurred. The criminal logic is simple: even an unverified claim can spook customers and push a company toward paying. US Bank has not confirmed any data loss, and US banking regulators require prompt disclosure when customer information is genuinely at risk, so the absence of a formal notice matters.

The Log4j problem refuses to go away

A fresh scare surfaced around Log4j, a piece of open-source software, meaning software built and shared freely by volunteers, that millions of organisations use to keep records of computer activity. A critical flaw discovered in it back in late 2021 allowed attackers to run their own code remotely on vulnerable systems, what security researchers call an RCE, or remote code execution, vulnerability.

Patches exist and have existed for years. The recurring problem is that Log4j is embedded deep inside countless products, and some organisations still have not applied the fix. If your software vendor has issued a Log4j-related update and you have not installed it, that is the single most useful thing you can do today.

Story Organisation Status
Airport cyberattack Manchester Airports Group Confirmed, investigation ongoing
Breach data validity Carhartt Partly fabricated
Ransomware claim US Bank Disputed by the bank
Log4j RCE scare Widespread (open-source) Patch available since Dec 2021
© 2026 Threat Vectr